International Code Council
ent_6d1326b97b57e33e4b9d6c5b
Disclosures
6
State AG · 4 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
252
as filed · State AG MA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- International Code Council
- Normalized
- international code council— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (6)newest first
- New Hampshire State AGas victim2026-08-18
International Code Council, Inc. discovered on July 2, 2026, that an unauthorized third party inserted a fraudulent payment page on its e-commerce website between June 30 and July 3, 2026. Customers may have entered names, full payment card numbers, CVVs, and expiration dates on this fake page. The incident affected 3 New Hampshire residents. ICC secured the website, investigated, and offered 12 months of complimentary identity protection services through IDX. Notifications were sent on August 18, 2026.
- Massachusetts State AGas victim2026-08-01
International Code Council, Inc. notified Massachusetts residents that an unauthorized third party collected payment card information entered on its website between June 30, 2026, and July 3, 2026. The company offered 12 months of complimentary identity protection services.
- Montana State AGas victim2017-01-27
International Code Council notified affected individuals of a security incident discovered on December 16, 2016, involving unauthorized access to payment card information. The unauthorized access occurred between April 25, 2016, and September 14, 2016. Compromised data included names, addresses, and credit/debit card details. The incident was contained, and the organization engaged forensic investigators and enhanced security measures.
- New Hampshire State AGas victim2017-01-27
International Code Council (ICC) notified the NH Attorney General of a data security incident affecting 71 NH residents. ICC discovered the issue on Dec 16, 2016, involving unauthorized access to its online store payment processing system. Compromised data included names, addresses, and credit/debit card info, occurring in two windows in 2016. ICC contained the incident, engaged forensic investigators, and implemented security upgrades.
- California State AGas victim2017-01-27
International Code Council (ICC) notified the California AG of a data breach affecting customer payment card information. The incident involved unauthorized access to credit/debit card data, including names and addresses, during two periods in 2016. ICC discovered the issue on December 16, 2016, and contained the incident. Remediation included website/server security updates, firewall installation, and staff training.
- Massachusetts State AGas victim2017-01-27
International Code Council reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-01-27. 252 Massachusetts residents were affected. The report records the breach type as electronic.